Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP on OPT If working but no Access to WAN [SOLVED]

    Scheduled Pinned Locked Moved Routing and Multi WAN
    6 Posts 2 Posters 694 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • noplanN
      noplan
      last edited by noplan

      Hi,

      driving me insane!

      DHCP Server on opt interface working fine, but not able to get the clients to get access to the internet (WAN)

      screenshot from fw rules on OPT
      opt IP 172.20.20.0/24

      any hints for getting this to work ?!? thx in advance

      0_1536081427712_54ec2cc6-a002-47ed-a1d4-bf8d045cd619-grafik.png

      the problem we are facing is, that DHCP ist working fine on that OPT interface,
      but we are not able to reach internet (browse the web) with the credentials (ip / mask /gateway/ dns) served by the DHCP server running on that OPT interface.

      using the diagnostic tool on the firewall
      diagnostics -> ping (source adress is this OPT interface) everything works.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Manual outbound NAT? Did you add the rules for the 172.20.20.0/24 source network?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • noplanN
          noplan
          last edited by noplan

          please note that i changed th ips from 172.20.20.0/24 to 172.31.31.0/28 and 172.32.32.0/28

          for outbound NAT this:

          0_1537634589533_a89f2df9-c22a-4e7f-9f62-1b8ad464259a-grafik.png

          and this

          0_1537634657328_0641b9dd-a195-4dbf-b371-443e3e50888f-grafik.png

          hybrid outbound NAT is used for openVPN reasons

          thx in advance

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            And you updated your firewall rules?

            The clients have pfSense as their default gateway?

            There really isn't much else to it.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • noplanN
              noplan
              last edited by

              hi,

              yes of course all updated
              all double checked (with pen pen and paper)

              default GW is set and also provided to clients (yes checked cuz pfsense is default GW for Clients)

              NAT was a cool hint (thank you) but also set.

              Thats why this is driving me nuts.

              i'll do some testing with another network port and come back later,
              cuz as u mentioned "There really isn't much else to it."

              thx in andvance

              noplanN 1 Reply Last reply Reply Quote 0
              • noplanN
                noplan @noplan
                last edited by

                @noplan

                done the same again like the pen and paper check

                took the same switch (old habits die hard)

                same problem --> wtf

                took a brand new switch

                workin like a charm

                checked the old switch .... some crazy folk just done some MAC ACL testing on some random ports
                reset the old switch now workin like a charm
                so SOLVED

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.